summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
-rw-r--r--config/initializers/session_store.rb4
1 files changed, 3 insertions, 1 deletions
diff --git a/config/initializers/session_store.rb b/config/initializers/session_store.rb
index 36c5f4666a7..e777ae2b78d 100644
--- a/config/initializers/session_store.rb
+++ b/config/initializers/session_store.rb
@@ -1,6 +1,8 @@
# Be sure to restart your server when you modify this file.
-Gitlab::Application.config.session_store :cookie_store, key: '_gitlab_session'
+Gitlab::Application.config.session_store :cookie_store, key: '_gitlab_session',
+ secure: Gitlab::Application.config.force_ssl,
+ httponly: true
# Use the database for sessions instead of the cookie-based default,
# which shouldn't be used to store highly confidential information